Vulnerabilities > Polycom > Low

DATE CVE VULNERABILITY TITLE RISK
2019-06-24 CVE-2019-10689 Improper Authentication vulnerability in Polycom products
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
low complexity
polycom CWE-287
3.3
2019-06-13 CVE-2018-10946 Information Exposure vulnerability in Polycom Realpresence Debut Firmware
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password via the admin web UI.
low complexity
polycom CWE-200
2.7
2019-06-13 CVE-2018-10947 Improper Input Validation vulnerability in Polycom Realpresence Debut Firmware
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset only after a Debut is rebooted.
2.9
2018-11-15 CVE-2018-14934 Incorrect Permission Assignment for Critical Resource vulnerability in Polycom Trio 8500 Firmware
The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control.
low complexity
polycom CWE-732
3.3
2015-09-03 CVE-2015-1516 Cross-site Scripting vulnerability in Polycom Realpresence Cloudaxis Suite
Cross-site scripting (XSS) vulnerability in Polycom RealPresence CloudAXIS Suite before 1.7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
network
polycom CWE-79
3.5